Microsoft-Windows-Winsock-NameResolution
16 events across 1 channel
Event ID 1000: GetAddrInfoW is called for queryName NodeName, serviceName ServiceName, flags Flags, family Family, socketType SocketType, protocol Protocol and seq Location.
#Description
GetAddrInfoW is called for queryName NodeName, serviceName ServiceName, flags Flags, family Family, socketType SocketType, protocol Protocol and seq Location.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | |
ServiceName UnicodeString | |
Location UInt32 | |
Flags UInt32 | |
Family UInt32 | |
SocketType UInt32 | |
Protocol UInt32 | Known values
|
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:41.692985+00:00",
"event_record_id": 17,
"correlation": {
"ActivityID": "4EC9235F-7114-46CF-A033-E58E6B97986C"
},
"execution": {
"process_id": 832,
"thread_id": 3636
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "ludus",
"ServiceName": "NULL",
"Location": 118,
"Flags": 5,
"Family": 0,
"SocketType": 0,
"Protocol": 0
},
"message": ""
}
Event ID 1001: GetAddrInfoW is completed for queryName NodeName with status Status and result Result.
#Description
GetAddrInfoW is completed for queryName NodeName with status Status and result Result.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | |
Status UInt32 | NTSTATUS reference |
Result UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1001,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:41.692988+00:00",
"event_record_id": 18,
"correlation": {
"ActivityID": "4EC9235F-7114-46CF-A033-E58E6B97986C"
},
"execution": {
"process_id": 832,
"thread_id": 3636
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "ludus",
"Status": 11001,
"Result": ""
},
"message": ""
}
Event ID 1002: GetAddrInfoExW is called for queryName NodeName, serviceName ServiceName, nameSpace NameSpace, nameSpace GUID NameSpaceGuid, flags Flags, family Family, socketType SocketType, protocol protocol, in...
#Description
GetAddrInfoExW is called for queryName NodeName, serviceName ServiceName, nameSpace NameSpace, nameSpace GUID NameSpaceGuid, flags Flags, family Family, socketType SocketType, protocol protocol, interface index InterfaceIndex, timeOut TimeOutInSec, asyncWithCallBack AsyncWithCallback, asyncWithOverlapped AsyncWithOverlapped and seq Location
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | |
ServiceName UnicodeString | |
Location UInt32 | |
NameSpace UInt32 | |
NameSpaceGuid GUID | |
Flags UInt32 | |
Family UInt32 | |
SocketType UInt32 | |
protocol UInt32 | |
InterfaceIndex UInt32 | |
TimeOutInSec UInt32 | |
AsyncWithCallback UInt32 | |
AsyncWithOverlapped UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1002,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033434+00:00",
"event_record_id": 188,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "us-v20.events.endpoint.security.microsoft.com",
"ServiceName": "NULL",
"Location": 226,
"NameSpace": 12,
"NameSpaceGuid": "00000000-0000-0000-0000-000000000000",
"Flags": 131074,
"Family": 0,
"SocketType": 1,
"protocol": 6,
"InterfaceIndex": 0,
"TimeOutInSec": 0,
"AsyncWithCallback": 0,
"AsyncWithOverlapped": 1
},
"message": ""
}
Event ID 1003: GetAddrInfoExW asynchronous query is pending for queryName: NodeName with cancel Handle CancelHandle.
#Description
GetAddrInfoExW asynchronous query is pending for queryName: NodeName with cancel Handle CancelHandle.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | |
CancelHandle UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1003,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033473+00:00",
"event_record_id": 195,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "us-v20.events.endpoint.security.microsoft.com",
"CancelHandle": 0
},
"message": ""
}
Event ID 1004: GetAddrInfoExW is completed for queryName NodeName with status Status and result Result.
#Description
GetAddrInfoExW is completed for queryName NodeName with status Status and result Result.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | |
Status UInt32 | NTSTATUS reference |
Result UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1004,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.072980+00:00",
"event_record_id": 206,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "us-v20.events.endpoint.security.microsoft.com",
"Status": 0,
"Result": "20.42.65.85;"
},
"message": ""
}
Event ID 1005: GetAddrInfoExCancel is called for query CancelHandle and seq Location.
#Event ID 1006: NSPLookupServiceBegin is called for provider ProviderGUID, queryName QueryName, serviceGUID ServiceGUID, interface index InterfaceIndex and control flags ControlFlags.
#Description
NSPLookupServiceBegin is called for provider ProviderGUID, queryName QueryName, serviceGUID ServiceGUID, interface index InterfaceIndex and control flags ControlFlags.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | |
QueryName UnicodeString | |
ServiceGUID GUID | |
InterfaceIndex UInt32 | |
ControlFlags UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1006,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033445+00:00",
"event_record_id": 189,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"QueryName": "us-v20.events.endpoint.security.microsoft.com",
"ServiceGUID": "0002A803-0000-0000-C000-000000000046",
"InterfaceIndex": 0,
"ControlFlags": 3146000
},
"message": ""
}
Event ID 1007: NSPLookupServiceBegin is completed for provider ProviderGUID, queryName QueryName serviceGUID ServiceGUID, interface index InterfaceIndex, control flags ControlFlags and lookup handle LookupHandle ...
#Description
NSPLookupServiceBegin is completed for provider ProviderGUID, queryName QueryName serviceGUID ServiceGUID, interface index InterfaceIndex, control flags ControlFlags and lookup handle LookupHandle with status Status.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | |
QueryName UnicodeString | |
ServiceGUID GUID | |
InterfaceIndex UInt32 | |
ControlFlags UInt32 | |
LookupHandle UInt64 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1007,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033450+00:00",
"event_record_id": 190,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"QueryName": "us-v20.events.endpoint.security.microsoft.com",
"ServiceGUID": "0002A803-0000-0000-C000-000000000046",
"InterfaceIndex": 0,
"ControlFlags": 3146000,
"LookupHandle": 1894238103792,
"Status": 0
},
"message": ""
}
Event ID 1008: NSPLookupServiceNext is called for provider ProviderGUID, control Flags ControlFlags and lookup handle LookupHandle.
#Description
NSPLookupServiceNext is called for provider ProviderGUID, control Flags ControlFlags and lookup handle LookupHandle.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | |
ControlFlags UInt32 | |
LookupHandle UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1008,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033491+00:00",
"event_record_id": 196,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"ControlFlags": 0,
"LookupHandle": 1894238104368
},
"message": ""
}
Event ID 1009: NSPLookupServiceNext is completed for provider ProviderGUID, control Flags ControlFlags and lookup Handle LookupHandle with status Status and result Result.
#Description
NSPLookupServiceNext is completed for provider ProviderGUID, control Flags ControlFlags and lookup Handle LookupHandle with status Status and result Result.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | |
ControlFlags UInt32 | |
LookupHandle UInt64 | |
Status UInt32 | NTSTATUS reference |
Result UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1009,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033541+00:00",
"event_record_id": 198,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 7344
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"ControlFlags": 0,
"LookupHandle": 1894238103792,
"Status": 11001,
"Result": ""
},
"message": ""
}
Event ID 1010: NSPLookupServiceEnd is called for provider ProviderGUID and lookup handle LookupHandle.
#Description
NSPLookupServiceEnd is called for provider ProviderGUID and lookup handle LookupHandle.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | |
LookupHandle UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1010,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033551+00:00",
"event_record_id": 199,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 7344
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"LookupHandle": 1894238103792
},
"message": ""
}
Event ID 1011: NSPLookupServiceEnd completed for provider ProviderGUID and lookup handle LookupHandle with status Status.
#Description
NSPLookupServiceEnd completed for provider ProviderGUID and lookup handle LookupHandle with status Status.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | |
LookupHandle UInt64 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1011,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033553+00:00",
"event_record_id": 200,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 7344
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"LookupHandle": 1894238103792,
"Status": 0
},
"message": ""
}
Event ID 1012: GetAddrInfoExW info.
#Description
GetAddrInfoExW info. queryName NodeName, serviceName ServiceName, nameSpace NameSpace, nameSpace GUID NameSpaceGuid, flags Flags, family Family, socketType SocketType, protocol protocol, interface index InterfaceIndex, timeOut TimeOutInSec, asyncWithCallBack AsyncWithCallback, asyncWithOverlapped AsyncWithOverlapped, error Error and seq Location
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | |
ServiceName UnicodeString | |
Location UInt32 | |
NameSpace UInt32 | |
NameSpaceGuid GUID | |
Flags UInt32 | |
Family UInt32 | |
SocketType UInt32 | |
protocol UInt32 | |
InterfaceIndex UInt32 | |
TimeOutInSec UInt32 | |
AsyncWithCallback UInt32 | |
AsyncWithOverlapped UInt32 | |
Error Int32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1012,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033417+00:00",
"event_record_id": 187,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "us-v20.events.endpoint.security.microsoft.com",
"ServiceName": "NULL",
"Location": 307,
"NameSpace": 12,
"NameSpaceGuid": "00000000-0000-0000-0000-000000000000",
"Flags": 131074,
"Family": 0,
"SocketType": 1,
"protocol": 6,
"InterfaceIndex": 0,
"TimeOutInSec": 0,
"AsyncWithCallback": 0,
"AsyncWithOverlapped": 1,
"Error": 0
},
"message": ""
}
Event ID 1013: Wsa Startup.
#Description
Wsa Startup. seq: Location.
Message #
Fields #
| Name | Description |
|---|---|
Location UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1013,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:38.230772+00:00",
"event_record_id": 1,
"correlation": {
"ActivityID": "DF92C490-B30B-0005-A2C8-92DF0BB3DC01"
},
"execution": {
"process_id": 6952,
"thread_id": 6108
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"Location": 101
},
"message": ""
}
Event ID 1014: Wsa Cleanup.
#Description
Wsa Cleanup. seq: Location. Refcount: RefCount.
Message #
Fields #
| Name | Description |
|---|---|
Location UInt32 | |
RefCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1014,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:38.230787+00:00",
"event_record_id": 2,
"correlation": {
"ActivityID": "DF92C490-B30B-0005-A2C8-92DF0BB3DC01"
},
"execution": {
"process_id": 6952,
"thread_id": 6108
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"Location": 201,
"RefCount": 2
},
"message": ""
}
Event ID 1015: NSJOB info.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {55404E71-4DB9-4DEB-A5F5-8F86E46DDE56}
Defined in ws2_32.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.2849, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02